Bug 2495997 (CVE-2026-58379)

Summary: CVE-2026-58379 gimp: gimp: Heap buffer overflow in read_channel_data()
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-01 15:06:14 UTC
A heap buffer overflow write vulnerability exists in GIMP's Paint Shop Pro (PSP) file format parser. In read_channel_data() in file-psp.c, for low bit-depth images (depth=1 or 4), line_width uses a packed formula (8 pixels/byte) but fread() reads width bytes (1 byte/pixel). For example, with width=33 and depth=1: allocates 4 bytes, writes 33 — a 29-byte heap overflow.

This is a variant of CVE-2026-4153 (commit 98cb1371), which fixed read_layer_block() but left the buf allocation in read_channel_data() unpatched.

- Function: read_channel_data()
- File: plug-ins/common/file-psp.c:1558-1784
- Fix: https://gitlab.gnome.org/GNOME/gimp/-/commit/b630f167
- Hardening: https://gitlab.gnome.org/GNOME/gimp/-/commit/20b00d6d
- Upstream issue: https://gitlab.gnome.org/GNOME/gimp/-/issues/16205
- Acknowledgment: bb1abu

Comment 1 errata-xmlrpc 2026-07-13 06:40:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:38496 https://access.redhat.com/errata/RHSA-2026:38496